Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

    Now that this information is public none of us 
    will give out our usernames to external websites, 
    thus ending the problem.
Correct me if I'm wrong, as I'm NOT a web guru, but I think there are three ways to get the user names, and it's enough if this only works in some cases:

(1) Brute force (look at who's currently active on the site)

(2) Look at browser history (HN users have to constantly look at their own profile to check for replies, and the URL contains their user name)

(3) Send whatever request the browser sends to HN normally, and gets the user name embedded in the page.

Again, I don't know enough about browsers/JS/HTTP/HN to know if any of the above would work. I'm just saying I'm not sure that explicitly giving out your user name is required for this.

Edit: typos



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: